SSL or TLS? The Difference and Current State
· SSL Basics
The term "SSL certificate" is so ubiquitous that many assume SSL and TLS are the same thing. They're not — and the difference matters for your server configuration.
Historical Timeline
SSL was developed by Netscape in the 1990s. SSL 2.0 and 3.0 contained critical vulnerabilities; the POODLE attack (2014) against SSL 3.0 forced its complete deprecation. TLS (Transport Layer Security) replaced SSL: TLS 1.0 (1999, now insecure), TLS 1.1 (2006, deprecated), TLS 1.2 (2008, still widely used), TLS 1.3 (2018, current gold standard).
TLS 1.3 Improvements
TLS 1.3 dramatically simplifies the handshake (fewer round trips), removes weak algorithms (RSA key exchange, RC4, DES), supports only strong ciphers (AES-GCM, ChaCha20-Poly1305), and introduces 0-RTT for faster reconnection.
Current State
All modern browsers support TLS 1.2 and 1.3 and block SSL 2.0/3.0 and TLS 1.0/1.1. Configure your server to accept only TLS 1.2 and 1.3.
Why Still Called "SSL Certificate"?
Industry habit. The X.509 certificate standard predates TLS, and the term stuck. What you buy is a digital certificate that works with the TLS protocol.
Visit the PekiSSL product page to find the right certificate for your needs.